You have a document / file.

20 tools that take a document / file as input. Filter them further.

Interactive malware sandbox: run a file or URL in a virtual machine and watch its processes, network traffic and indicators live.

  • Website
  • Freemium
  • Account

TakesDocument / fileURLFile hash

Extracts text and metadata (author, software, dates) from over a thousand file types, including Office files and PDFs.

  • Command line
  • Free

TakesDocument / fileImage

Reads and edits metadata in images, video, audio and documents, such as camera model, GPS coordinates, timestamps, author and software.

  • Command line
  • Free

TakesImageVideoDocument / file

The NSA's open-source reverse-engineering suite: disassembles and decompiles executables to show what a program really does.

  • Desktop app
  • Free

TakesDocument / file

Python tools (hachoir-metadata) that read metadata from dozens of binary file formats, including ones other tools skip.

  • Command line
  • Freemium

TakesDocument / fileImageVideo

Free OCR in 100+ languages: extract text from images and scanned PDFs so you can translate or search it.

  • Website
  • Free

TakesImageDocument / file

Identifies which ransomware encrypted your files from a ransom note, an encrypted sample or the contact email, and says whether a decryptor exists.

  • Website
  • Free

TakesDocument / fileEmail address

Extracts IPs, URLs, domains, emails and hashes from reports and text, including "defanged" ones like hxxp and [.].

  • Command line
  • Free

TakesDocument / file

Malware sandbox for Windows, Android, macOS and Linux samples and URLs. Reports behaviour, network traffic and indicators.

  • Website
  • Freemium

TakesDocument / fileFile hashURL

Scans a file with a dozen antivirus engines at once, or looks up earlier scans of the same file.

  • Website
  • Free

TakesDocument / fileFile hash

Community platform for Android malware: look up an app by hash or package name to see detections, analyses and analyst comments.

  • Website
  • Freemium

TakesDocument / fileFile hash

Malware sandbox that detonates files and URLs, and lets you search past public reports by IP, domain or hash.

  • Website
  • Freemium

TakesDocument / fileURLFile hashIP addressDomain

Shows all metadata in images, videos, audio, documents and e-books in the browser.

  • Website
  • Freemium

TakesImageVideoDocument / file

Scans files, hashes, URLs and IPs with 20+ antivirus engines and a sandbox, and shows the verdict from each.

  • Website
  • Freemium

TakesFile hashDocument / fileURLIP address

Extracts hosts, files, images, credentials and sessions from a network capture (PCAP) for forensic review.

  • Desktop app
  • Free

TakesDocument / file

pdfid and pdf-parser: scan a PDF for risky elements like JavaScript and embedded files, then extract them for analysis.

  • Command line
  • Free

TakesDocument / file

Scans Office documents and PDFs for exploits and hidden macros and scores how likely the file is to be malicious.

  • Website
  • Freemium

TakesDocument / file

Extracts the configuration from malware samples without running them, revealing command-and-control servers and keys.

  • Website
  • Free

TakesFile hashDocument / file

Scans files, URLs, domains, IPs and hashes with 70+ security engines and shows how they relate to one another.

  • Website
  • Freemium

TakesFile hashURLDomainIP addressDocument / file

The standard network protocol analyser: capture traffic or open a PCAP and inspect every packet.

  • Desktop app
  • Free

TakesDocument / file